Vulnerability Name:

CVE-2019-17054 (CCN-168361)

Assigned:2019-09-24
Published:2019-09-24
Updated:2019-10-25
Summary:atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
CVSS v3 Severity:3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-276
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2019-17054

Source: MISC
Type: UNKNOWN
http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html

Source: XF
Type: UNKNOWN
linux-kernel-cve201917054-sec-bypass(168361)

Source: CCN
Type: Linux Kernel GIT Repository
Merge branch 'check-CAP_NEW_RAW'

Source: MISC
Type: Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0edc3f703f7bcaf550774b5d43ab727bcd0fe06b

Source: MISC
Type: Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=6cc03e8aa36c51f3b26a0d21a3c4ce2809c842ac

Source: MLIST
Type: UNKNOWN
[debian-lts-announce] 20200118 [SECURITY] [DLA 2068-1] linux security update

Source: MLIST
Type: UNKNOWN
[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update

Source: FEDORA
Type: UNKNOWN
FEDORA-2019-41e28660ae

Source: BUGTRAQ
Type: UNKNOWN
20191108 [slackware-security] Slackware 14.2 kernel (SSA:2019-311-01)

Source: UBUNTU
Type: UNKNOWN
USN-4184-1

Source: UBUNTU
Type: UNKNOWN
USN-4185-1

Source: UBUNTU
Type: UNKNOWN
USN-4185-2

Source: UBUNTU
Type: UNKNOWN
USN-4186-1

Source: UBUNTU
Type: UNKNOWN
USN-4186-2

Source: CCN
Type: IBM Security Bulletin 6116992 (Spectrum Protect Plus)
Multiple vulnerabilities in Linux Kernel affect IBM Spectrum Protect Plus

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2019-17054

Vulnerable Configuration:Configuration 1:
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:* (Version <= 5.3.2)

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:5.3.2:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:spectrum_protect_plus:10.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_protect_plus:10.1.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201917054
    V
    CVE-2019-17054
    2022-09-02
    oval:org.opensuse.security:def:33109
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:34017
    P
    Security update for chrony (Moderate)
    2021-12-22
    oval:org.opensuse.security:def:30278
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:33052
    P
    Security update for openexr (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:31313
    P
    Security update for ruby2.1 (Important)
    2021-12-01
    oval:org.opensuse.security:def:31292
    P
    Security update for strongswan (Important)
    2021-10-19
    oval:org.opensuse.security:def:34552
    P
    Security update for python-urllib3 (Moderate)
    2021-09-29
    oval:org.opensuse.security:def:34551
    P
    Security update for atftp (Moderate)
    2021-09-27
    oval:org.opensuse.security:def:31253
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:33960
    P
    Security update for cpio (Important)
    2021-08-23
    oval:org.opensuse.security:def:30223
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:34478
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:33941
    P
    Security update for libsolv (Important)
    2021-06-28
    oval:org.opensuse.security:def:31204
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:36085
    P
    apache2-mod_perl-2.0.4-40.24.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:34434
    P
    Security update for graphviz (Critical)
    2021-05-19
    oval:org.opensuse.security:def:33645
    P
    Security update for samba (Important)
    2021-05-04
    oval:org.opensuse.security:def:33902
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:30070
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:34409
    P
    Security update for qemu (Important)
    2021-04-16
    oval:org.opensuse.security:def:32896
    P
    Security update for xorg-x11-server (Important)
    2021-04-14
    oval:org.opensuse.security:def:33634
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:33633
    P
    Security update for xorg-x11-server (Important)
    2021-04-13
    oval:org.opensuse.security:def:31148
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:34647
    P
    Security update for wpa_supplicant (Important)
    2021-03-08
    oval:org.opensuse.security:def:33728
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:34563
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:35247
    P
    Security update for the Linux Kernel (Important)
    2021-01-15
    oval:org.opensuse.security:def:31357
    P
    Security update for MozillaFirefox (Important)
    2021-01-12
    oval:org.opensuse.security:def:28860
    P
    Security update for mutt (Important)
    2020-12-07
    oval:org.opensuse.security:def:36044
    P
    taglib-1.5-19.23.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:30553
    P
    Security update for Samba
    2020-12-01
    oval:org.opensuse.security:def:27993
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33197
    P
    log4net on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30542
    P
    Security update for kdelibs4
    2020-12-01
    oval:org.opensuse.security:def:27909
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:33158
    P
    libltdl7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29889
    P
    Security update for SUSE Linux Enterprise Server 11 SP1 Kernel for Teradata (Important)
    2020-12-01
    oval:org.opensuse.security:def:30541
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27852
    P
    Security update for perl
    2020-12-01
    oval:org.opensuse.security:def:29853
    P
    Security update for Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:27770
    P
    Security update for IBM Java
    2020-12-01
    oval:org.opensuse.security:def:29215
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:27642
    P
    Security update for LibreOffice
    2020-12-01
    oval:org.opensuse.security:def:29171
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27578
    P
    wireshark on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32809
    P
    xorg-x11-Xvnc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29154
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35156
    P
    Security update for the SUSE Linux Enterprise 11 SP3 Kernel for Teradata (Important)
    2020-12-01
    oval:org.opensuse.security:def:27567
    P
    silc-toolkit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32752
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29115
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:35116
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27566
    P
    sendmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32658
    P
    evolution-data-server on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29066
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:32523
    P
    gnutls on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29012
    P
    Security update for hawk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32445
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:32434
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:28776
    P
    Security update for libwmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34370
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31104
    P
    Security update for the SUSE Linux Enterprise 11 SP3 Kernel for Teradata (Important)
    2020-12-01
    oval:org.opensuse.security:def:32433
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:28719
    P
    Security update for kdebase4-workspace (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34321
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:31067
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28634
    P
    Security update for augeas
    2020-12-01
    oval:org.opensuse.security:def:34263
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30429
    P
    Security update for xorg-x11-libxcb
    2020-12-01
    oval:org.opensuse.security:def:28503
    P
    Security update for openssh-openssl1 (Critical)
    2020-12-01
    oval:org.opensuse.security:def:34106
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:30385
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:28435
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30366
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28424
    P
    Security update for wireshark (Low)
    2020-12-01
    oval:org.opensuse.security:def:30327
    P
    Security update for tiff (Low)
    2020-12-01
    oval:org.opensuse.security:def:28423
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33864
    P
    Security update for jasper
    2020-12-01
    oval:org.opensuse.security:def:35406
    P
    Security update for openssh-openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:35362
    P
    Security update for nagios-plugins
    2020-12-01
    oval:org.opensuse.security:def:35335
    P
    Security update for mozilla-nspr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29984
    P
    Security update for libsoup (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35296
    P
    Security update for libxml2 (Low)
    2020-12-01
    oval:org.opensuse.security:def:32033
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29927
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31995
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29840
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:35188
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29708
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:35029
    P
    Security update for guile (Low)
    2020-12-01
    oval:org.opensuse.security:def:29635
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:34939
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:29624
    P
    Security update for Mono
    2020-12-01
    oval:org.opensuse.security:def:34882
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29016
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29623
    P
    Security update for bsdtar (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34783
    P
    Recommended update for NetworkManager-kde4 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28981
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28343
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30993
    P
    Security update for jasper
    2020-12-01
    oval:org.opensuse.security:def:28299
    P
    Security update for netatalk (Important)
    2020-12-01
    oval:org.opensuse.security:def:30906
    P
    Security update for freeradius-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28285
    P
    Security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30849
    P
    Security update for dhcp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28246
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30759
    P
    Security update for apache2-mod_nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28197
    P
    Security update for libexif (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33264
    P
    sysconfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30627
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:28144
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:33220
    P
    opie on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.disco:def:2019170540000000
    V
    CVE-2019-17054 on Ubuntu 19.04 (disco) - medium.
    2019-10-01
    oval:com.ubuntu.bionic:def:2019170540000000
    V
    CVE-2019-17054 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-10-01
    oval:com.ubuntu.xenial:def:2019170540000000
    V
    CVE-2019-17054 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-10-01
    BACK
    linux linux kernel *
    linux linux kernel 5.3.2
    ibm spectrum protect plus 10.1.0
    ibm spectrum protect plus 10.1.5